Financial Security Institute traces attack IPs and logs at Shinhan Bank, confirming ARTEX use

Two savings banks also under investigation as breach scope widens

FSC to recommend comprehensive audit of internal employee-facing systems

ATM machines from major commercial banks clustered in central Seoul. (Yoon Chang-bin/The Korea Herald)
ATM machines from major commercial banks clustered in central Seoul. (Yoon Chang-bin/The Korea Herald)

A Chinese-developed AI-based penetration-testing platform called ARTEX AI has been confirmed as the tool used in a string of personal data breaches at major South Korean banks, an investigation has found. Questions had long circulated in the cybersecurity industry about whether AI was involved, and the Korea Financial Security Institute said its probe has now turned up clear evidence the tool was used. Two savings banks are also under investigation for attacks of the same type, raising the possibility that the total damage could grow further.

A Korea Financial Security Institute official said Saturday in a phone call with The Herald Business that investigators traced the attack IPs and server logs from Shinhan Bank — the first institution to report an incident — and found evidence pointing to ARTEX. The official confirmed that suspicions raised by the security industry about ARTEX's involvement were accurate.

ARTEX AI is an open-source, LLM-based autonomous penetration-testing system distributed primarily through GitHub and aimed at Chinese-speaking users. The official drew a line, however, stressing that the AI did not carry out attacks on its own. "It is true that AI was used in the attacks, but the AI did not act independently without human involvement," the official said. "A hacker used the AI as a tool."

'Attackers keep switching IPs — but the method is identical'

The attacks are believed to have been concentrated between Sunday and Thursday. Additional victims came to light after the institute shared the attacker IPs identified during its Shinhan Bank investigation with the broader financial sector. Individual banks then conducted full reviews of access logs tied to those IPs and belatedly discovered and reported breaches of their own.

Multiple IPs were used across the attacks, with two to three overlapping at each bank. When one IP is blocked, the attacker switches to another and continues — activity that is still ongoing. "Blocking IPs is little more than emergency first aid," the official said, adding that the attack method and the vulnerabilities being exploited remain the same regardless of which IP is used. "When you analyze the attack data, there is a specific data signature common to traffic originating from ARTEX, which allows us to identify the attacker," the official said.

On whether the attacks are linked to a previously reported hack of the Government24 portal, the official said investigators cannot access that data to verify a connection, but added: "The timing is so far apart that we suspect it is not the work of the same attacker."

Korea Financial Security Institute
Korea Financial Security Institute

Employee-facing systems exposed — will network-separation rollback stall?

Every attack targeted internal employee or partner-facing systems rather than customer-facing internet or mobile banking services. Shinhan Bank said 25,729 people's data was exposed through a loan-agent inquiry service; KB Kookmin Bank reported 119 records leaked from an employee mobile work-support system; Hana Bank said 89 records were taken from an employee sales-support system known as ODS. BNK Busan Bank also reported that information on 11 contract workers was exposed.

"Security on customer-facing electronic financial services has been enormously strengthened, but internal employee-facing systems had been managed less rigorously," the official said. "There are so many management points across such a wide scope that financial institutions themselves appear to have had difficulty identifying where those vulnerabilities existed."

Woori Bank and NH NongHyup Bank were targeted but sustained no breach because the specific vulnerabilities the attacker sought were not present in their systems. Financial institutions are not required to report incidents when no damage occurs.

The institute's investigation found that the attacks extended well beyond the banking sector. "Far more institutions were attacked than those that ended up with actual incidents," the official said, adding that organizations outside banking were also hit. The institute is particularly focused on two savings banks, analyzing their access logs to determine whether a breach occurred. Yegaram Savings Bank had already disclosed through a notice on its website that an unidentified hacker had gained access and caused a personal data leak.

The confirmed number of affected individuals currently stands at just under 26,000, but that figure could rise depending on the outcome of ongoing investigations. With breaches surfacing simultaneously across multiple financial institutions and the institute's response capacity stretched, there is no clear timeline for completing the probe. Because the attacks originated overseas, the institute has been sharing attacker IPs with police and coordinating with them since the first report was filed.

'Direct financial harm such as fund transfers unlikely'

The Korea Financial Security Institute believes the risk of direct financial loss to consumers is low. "The attacker did not take over the systems — they got in and extracted information by querying it," the official said. "The leaked personal data could be used for voice phishing and similar scams, but we do not expect funds to be directly transferred out of accounts."

The deeper concern is that attacks of the same type could be repeated at any time. "There are a great many open-source AI tools like ARTEX," the official said. "There is currently no way to restrict everything being developed and distributed around the world."

Financial regulators are preparing follow-up measures. The institute is drafting a recommendation that financial firms conduct a comprehensive audit of internal employee-facing systems among their external access points, and the Financial Services Commission plans to issue that recommendation to the financial sector.

The FSC views the simultaneous wave of attacks across multiple financial institutions as highly unusual. "The financial authorities recognize this situation — where multiple banks are experiencing similar problems all at once — as a very extraordinary set of circumstances," an FSC official said.

Because the attacks focused on internal employee-facing systems, some observers say the incidents could put the brakes on the regulatory push to relax network-separation rules. Domestic financial firms are subject to regulations requiring their business systems to be physically isolated from external networks for security reasons, but regulators have been running an emergency network-separation relaxation measure for AI security testing since June. Starting this month, the number of firms covered under the second phase of that relaxation expanded to 75 — up 26 from the 49 included in the first phase.


won@heraldcorp.com